Skip to content
5 min fix Updated 8 Aug 2026
Quick Answer

Turn off Wi-Fi or unplug the network cable, leave the computer switched on, and phone IT from another device with the words 'I have a ransomware message on my screen.' Do not pay, and do not click anything in the message.

What to Do If You See a Ransomware Message

Applies to: Windows 11, Windows 10, Microsoft 365, OneDrive
Article Type: Troubleshooting
Last Updated: 2026-08-08

Summary

A message on your screen says your files are encrypted and demands payment. The next five minutes matter more than the next five hours, and the right moves are not obvious under pressure. Work through the steps below in order — they stop the damage from spreading, keep your recovery options open, and get the right people involved fast.

Symptoms

  • A message fills the screen or sits in a window you cannot dismiss, claiming your files are encrypted and demanding payment — usually in cryptocurrency, often with a countdown timer.
  • Files will not open, their icons have turned blank or generic, and their names have gained an extension you have never seen, such as .locked, .crypt, or a string of random letters.
  • A text file with a name like README.txt, DECRYPT_INSTRUCTIONS.txt, or HOW_TO_RECOVER_FILES.txt has appeared in folder after folder.
  • A browser tab or popup claims your computer is locked or infected, plays an alarm sound, and shows a phone number to call. This one is almost certainly a scare page, not ransomware — Step 4 shows you how to tell.

Before You Start

  • None required — the first step needs no sign-in, no tools, and no admin rights.
  • Have your phone or a second device ready: you will use it to reach IT and to keep reading this guide while the affected computer stays untouched.

Instructions

1. Disconnect the Computer from the Network Now

Ransomware encrypts everything it can reach, so cutting the connection stops it spreading to shared drives and synced folders.

  1. If the computer is on Wi-Fi, click the network icon in the bottom-right corner of the taskbar, next to the clock. The Quick Settings panel opens.
  2. Click the Wi-Fi tile so it turns from blue to grey. The network name disappears and a globe icon with a slash replaces the Wi-Fi icon in the taskbar.
  3. If the computer uses a network cable, unplug the cable from the back or side of the machine.
  4. Unplug any external hard drive or USB stick. Anything on it that is not yet encrypted stays safe once it is disconnected.
  5. Leave the computer switched on. Do not restart it and do not shut it down — a reboot can destroy evidence IT needs to identify the strain, and with some strains it makes files harder to recover.

2. Do Not Pay and Do Not Click Anything in the Message

The message is the attacker's interface, and every button in it is hostile.

  • Do not pay, and do not start the payment process "to see what it costs." Payment funds the operation, marks you as someone who pays, and buys no guarantee of anything in return.
  • Do not click Decrypt, Support, Free trial decryption, or any other button or link in the message. The countdown timer exists to panic you into clicking.
  • Do not type anything into the message — not an email address, not a file name.
  • Leave the message on screen and photograph it with your phone, including any strange file extension you can see. The wording and the extension identify the strain, which shapes the entire recovery.

3. Report It by Phone, Not from the Infected Computer

A ransomware report jumps every IT queue, and calling from another device keeps the infected machine untouched.

  1. Pick up your phone, or use Teams on a second device, and contact your IT department or helpdesk directly.
  2. Open with these exact words: "I have a ransomware message on my screen. The computer is off the network and still switched on." That sentence tells them the severity and that containment is already done — it gets you escalated immediately.
  3. Then give them: what you were doing when the message appeared, the time it appeared, which shared drives or team sites you use, and the photo you took in Step 2.
  4. Follow their instructions from here, and do not touch the affected computer unless they ask you to. From this point the machine is evidence as well as a workstation.

4. Check Whether It Is Real Encryption or a Scare Page

Real ransomware and fake browser warnings demand the same panic but need opposite responses, and one look at your files settles it.

  1. Without clicking anything in the message, open File Explorer from the taskbar and look at your Documents folder.
  2. Real ransomware leaves fingerprints: file names have gained an odd extension, icons have gone blank or generic, and a file you double-click will not open. Ransom note text files sit in every folder.
  3. If your files open normally and the scary message lives in a browser window — a "locked computer" page, a virus warning with an alarm sound, a phone number to call — it is a scare page, not ransomware. Nothing on your disk is encrypted. Close the browser and follow How to Stop Fake Virus Pop-ups and Spam Notifications from Your Browser; if it imitates a blue Windows crash screen, see Understanding Fake BSOD Scams.
  4. If the fingerprints are real, continue with the steps below.

5. Let IT Drive the Recovery

Knowing what happens next takes the edge off the wait and stops well-meant improvisation from making things worse.

  1. Expect IT to take the machine. The standard path is to wipe and reinstall it rather than clean it — that is routine, not a sign your situation is unusually bad.
  2. Expect questions about your files: which folders matter most, and where they live — OneDrive, SharePoint, a shared drive. Files in OneDrive or SharePoint are usually recoverable from version history and Files Restore even when the local copies are encrypted.
  3. Expect your password to be reset and sessions to be signed out as a precaution. That is protective, not an accusation.
  4. Do not reconnect the computer to the network, plug in your external drive elsewhere, or try recovery tools from the internet while IT works. A drive that was plugged in during the attack needs scanning before it touches another machine.

6. Recover on Your Own If There Is No IT to Call

Working solo or in a business without IT support changes who does the work, not the order of the work.

  1. Keep the infected computer isolated — off the network, switched on, untouched. Everything below happens on a different, clean device.
  2. On the clean device, sign in at onedrive.com and check your files. If they are encrypted there too, roll your entire drive back to a point before the attack with Files Restore — the full walkthrough is How to Restore Your Entire OneDrive to an Earlier Time. Restore only after the infected computer is off the network, or it will encrypt the files again.
  3. If you keep an offline backup — an external drive you plug in for backups, or a second cloud service — leave it disconnected until the infected machine is dealt with, then restore from it onto a clean computer.
  4. The infected computer needs a full reset before it goes back online: Settings > System > Recovery > Reset this PC, choosing Remove everything. This erases the machine — and that costs you nothing extra, because what was on it is either already encrypted or already safe in your backup and OneDrive.
  5. Never buy a decryption tool or "ransomware removal service" from an ad or a forum. The people selling them to victims are running the second half of the same scam.

Troubleshooting

DANGER

Never pay, and never call a phone number shown in the message. Payment rarely brings files back and funds the next attack — and a "support line" in a security warning is the surest sign of a scam. Recovery comes from backups, version history, and Files Restore, all of which work without the attacker's cooperation.

Symptom / ErrorPotential CauseSolution
The message shows a phone number to call for helpTech-support scam pageReal ransomware demands cryptocurrency through its note; a support hotline means a scare page. Close the browser from Task Manager (Ctrl + Shift + Esc, select the browser, click End task) — nothing on your disk is encrypted.
Files on a shared or network drive will not open eitherSpread before disconnectionTell IT immediately, in these words: "Ransomware has reached the shared drive — please take it offline and restore from backup." Every minute it stays online, more of it is encrypted.
Your OneDrive files on the web are encrypted tooEncrypted copies synced upRecoverable. Use Files Restore at onedrive.com to roll the drive back to before the attack — see How to Restore Your Entire OneDrive to an Earlier Time.
The computer was restarted before anyone saw the messageReflex rebootKeep it off the network and tell IT what the message said, using your photo or memory of the wording and the file extension — the strain can still be identified from the encrypted files themselves.
The message came back after the computer was cleanedInfection survived the cleanupAsk IT to wipe and reinstall the machine rather than clean it again, and include the time the message reappeared and whether any external drive was plugged in since.